Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
PHPNuke-Clan 4.2.0 - 'mvcw_conver.php' Remote File Inclusion
CVE-2007-4606webappsphp
PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PN
23RISK
open
ReferênciaVexDay Proof
Postcast Server Pro 3.0.61 / Quiksoft EasyMail - 'emsmtp.dll 6.0.1' Remote Buffer Overflow
CVE-2007-4607remotewindows
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RISK
open
ReferênciaVexDay Proof
MWOpen E-Commerce - 'leggi_commenti.asp' SQL Injection
CVE-2007-6292webappsasp
SQL injection vulnerability in leggi_commenti.asp in MWOpen 1.4 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
phpBB Links MOD 1.2.2 - SQL Injection
CVE-2007-4653webappsphp
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote a
23RISK
open
ReferênciaVexDay Proof
eNetman 20050830 - 'index.php' Remote File Inclusion
CVE-2007-4712webappsphp
PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code
35RISK
open
ReferênciaVexDay Proof
Move Networks Quantum Streaming Player - Remote Overflow (SEH)
CVE-2007-4722remotewindows
Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie0705100
28RISK
open
ReferênciaVexDay Proof
OtsTurntables 1.00 - '.m3u' Local Buffer Overflow
CVE-2007-4734localwindows
Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a lon
23RISK
open
ReferênciaVexDay Proof
X-Cart - Multiple Remote File Inclusions
CVE-2007-4907webappsphp
Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a
23RISK
open
ReferênciaVexDay Proof
JetCast Server 2.0.0.4308 - Remote Denial of Service
CVE-2007-4911doswindows
JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a lo
23RISK
open
ReferênciaVexDay Proof
JBlog 1.0 - 'index.php?id' SQL Injection
CVE-2007-4919webappsphp
Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
PHP Webquest 2.5 - 'id_actividad' SQL Injection
CVE-2007-4920webappsphp
SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Joomla! Component joom12pic 1.0 - Remote File Inclusion
CVE-2007-4954webappsphp
PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla
28RISK
open
ReferênciaVexDay Proof
KwsPHP 1.0 - 'login.php' SQL Injection
CVE-2007-4956webappsphp
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) th
23RISK
open
ReferênciaVexDay Proof
Chupix CMS 0.2.3 - 'download.php' Remote File Disclosure
CVE-2007-4957webappsphp
Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overw
23RISK
open
ReferênciaVexDay Proof
Xforum 1.4 - 'topic' SQL Injection
CVE-2008-0279webappsphp
SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
DomPHP 0.81 - Remote Add Administrator
CVE-2008-0282webappsphp
SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Foojan Wms 1.0 - 'story' SQL Injection
CVE-2008-0447webappsphp
SQL injection vulnerability in index.php in Foojan WMS PHP Weblog 1.0 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Easysitenetwork Recipe - 'categoryId' SQL Injection
CVE-2008-0453webappsphp
SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Liquid-Silver CMS 0.1 - 'update' Local File Inclusion
CVE-2008-0459webappsphp
Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allo
23RISK
open
ReferênciaVexDay Proof
ActiveKB KnowledgeBase 2.x - 'catId' SQL Injection
CVE-2007-5131webappsphp
SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
PhFiTo 1.3.0 - 'SRC_PATH' Remote File Inclusion
CVE-2007-5157webappsphp
PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFido
23RISK
open
ReferênciaVexDay Proof
PHP Links 1.3 - 'id' SQL Injection
CVE-2008-0565webappsphp
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
ImageStation - 'SonyISUpload.cab 1.0.0.38' ActiveX Buffer Overflow (PoC)
CVE-2008-0748doswindows
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RISK
open
ReferênciaVexDay Proof
Joomla! Component MCQuiz 0.9 Final - 'tid' SQL Injection
CVE-2008-0800webappsphp
SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attack
23RISK
open
ReferênciaVexDay Proof
PhpBlock a8.4 - 'PATH_TO_CODE' Remote File Inclusion
CVE-2008-1776webappsphp
PHP remote file inclusion vulnerability in modules/basicfog/basicfogfactory.class.php in PhpBlock A8.4 allows remote att
28RISK
open
ReferênciaVexDay Proof
Prozilla Forum Service - 'forum' SQL Injection
CVE-2008-1789webappsphp
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Smeego 1.0 - 'Cookie lang' Local File Inclusion
CVE-2008-2352webappsphp
Directory traversal vulnerability in index.php in Smeego 1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Archangel Weblog 0.90.02 - 'post_id' SQL Injection
CVE-2008-2356webappsphp
SQL injection vulnerability in index.php in Archangel Weblog 0.90.02 and earlier allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
CVE-2007-5771webappsphp
Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie.
23RISK
open
ReferênciaVexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
CVE-2007-5773webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote atta
23RISK
open
previouspage 177 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.